Sonicwall · Sma1000 · CVE-2026-15410
**Name of the Vulnerable Software and Affected Versions**
SonicWall SMA 1000 series (affected versions not specified)
**Description**
An improper control of code generation issue exists in the Appliance Management Console (AMC). This flaw allows a remote authenticated attacker with administrator privileges to execute arbitrary operating system commands. Real-world exploitation has been observed by actor UTA0533, who used a chain of zero-day vulnerabilities to gain unauthorized access, perform lateral movement, and deploy malware. This activity included the use of a binary named `rootrun` for local privilege escalation to root and a malicious script called `KNUCKLEBALL` containing a proxy tool and a web shell to maintain external access.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.